CVEs (10,000)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Dec 7, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Guests can trigger deadlock in Linux netback driver T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The patch for XSA-392 introduced anothe...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Dec 7, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Guests can trigger deadlock in Linux netback driver T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The patch for XSA-392 introduced anothe...Show more |
2Debian Linux2Debian Linux Linux KernelJun 17, 2026 Dec 7, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Guests can trigger NIC interface reset/abort/crash via netback It is possible for a guest to trigger a NIC interface reset/abort/crash in a Linux based network backend by sending certain kinds of packets. It appears to b...Show more |
2Debian Videolan2Debian Linux Vlc Media PlayerJun 17, 2026 Dec 6, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 An integer overflow in the VNC module in VideoLAN VLC Media Player through 3.0.17.4 allows attackers, by tricking a user into opening a crafted playlist or connecting to a rogue VNC server, to crash VLC or execute code u...Show more |
3Debian FedoraprojectGitpython Project3Debian Linux FedoraGitpythonJun 17, 2026 Dec 6, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command. Exploiting...Show more |
A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if...Show more |
4Debian LlhttpNodejs+1 more4Debian Linux LlhttpNode.js+1 moreJun 17, 2026 Dec 5, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling. |
3Debian NodejsSiemens3Debian Linux Node.jsSinec InsJun 17, 2026 Dec 5, 2022 N/A· v4 9.1 CRITICAL· v3 N/A· v2 A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does...Show more |
5Apple DebianHaxx+2 more9Clustered Data Ontap CurlDebian Linux+6 moreJun 17, 2026 Dec 5, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was us...Show more |
2Debian Rack Project2Debian Linux RackJun 17, 2026 Dec 5, 2022 N/A· v4 10.0 CRITICAL· v3 N/A· v2 A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint and CommonLogger components of Rack. |
A possible denial of service vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 in the multipart parsing component of Rack. |
3Awstats DebianFedoraproject3Awstats Debian LinuxFedoraJun 17, 2026 Dec 4, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks. |
2Apache Debian2Commons Net Debian LinuxJun 17, 2026 Dec 3, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the maliciou...Show more |
2Debian G810 Led Project2Debian Linux G810 LedJun 17, 2026 Nov 30, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 g810-led 0.4.2, a LED configuration tool for Logitech Gx10 keyboards, contained a udev rule to make supported device nodes world-readable and writable, allowing any process on the system to read traffic from keyboards, i...Show more |
2Debian Sinatrarb2Debian Linux SinatraJun 17, 2026 Nov 28, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attac...Show more |
3Debian FedoraprojectGnu3Debian Linux EmacsFedoraJun 17, 2026 Nov 28, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the ctags progra...Show more |
4Debian FedoraprojectLinux+1 more8Debian Linux FedoraH300s Firmware+5 moreJun 17, 2026 Nov 27, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 An issue was discovered in the Linux kernel through 6.0.10. l2cap_config_req in net/bluetooth/l2cap_core.c has an integer wraparound via L2CAP_CONF_REQ packets. |
3Debian OpenjsfQs Project3Debian Linux ExpressQsJun 17, 2026 Nov 26, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express application because an __ proto__ key can be used. In many typical Express use cases, an...Show more |
3Artifex DebianFedoraproject3Debian Linux FedoraMujsJun 17, 2026 Nov 23, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 A logical issue in O_getOwnPropertyDescriptor() in Artifex MuJS 1.0.0 through 1.3.x before 1.3.2 allows an attacker to achieve Remote Code Execution through memory corruption, via the loading of a crafted JavaScript file...Show more |
2Debian Postgresql2Debian Linux Postgresql Jdbc DriverJun 17, 2026 Nov 23, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 pgjdbc is an open source postgresql JDBC Driver. In affected versions a prepared statement using either `PreparedStatement.setText(int, InputStream)` or `PreparedStatemet.setBytea(int, InputStream)` will create a tempora...Show more |